How to recover a stolen .ca domain under the applicable domain rules
How to recover a stolen .ca domain under the applicable domain rules. UDRP and ccTLD domain recovery and defense across .ca. Email the firm to assess your case.
Your .ca domain disappears from your registrar account overnight. The WHOIS record shows a name you do not recognize. Someone has redirected your traffic, your email is bouncing, and the domain that represents years of Canadian business presence is now in a stranger's hands. That is account compromise — domain theft — and it requires a different response than an ordinary trademark dispute.
To recover a stolen .ca domain you must work through two parallel tracks: an emergency registrar-lock escalation to freeze any further transfers, and either a CIRA CDRP proceeding or a court action to establish the legal right to retransfer. The CIRA Canadian Domain Name Dispute Resolution Policy (CDRP) applies specifically to .ca and requires the complainant to hold Canadian Presence Requirements. The timeline from verified compromise to formal filing typically spans a matter of days to a few weeks; acting within the first 24 to 72 hours is the single most important variable.
This page covers the CIRA CDRP test, the registrar mechanics, the evidence that decides stolen-domain cases, the situations where a court route is necessary, and the realistic next step for a brand owner or registrant whose .ca has been taken.
What makes a .ca theft different from a standard cybersquatting dispute?
Domain theft — also called unauthorized transfer or account hijacking — is not a cybersquatting dispute. The key distinction matters because it determines which remedy reaches your situation fastest. In a conventional dispute, the registrant registered the domain deliberately with your mark in mind. In a theft, you were the registrant; a third party obtained unauthorized access and transferred the domain out of your account.
That factual difference reshapes the evidence set. You are not trying to prove someone else's bad faith at registration. You are proving your own prior entitlement — the chain of registration, the account compromise, and the unauthorized transfer. CIRA's CDRP does address abusive registration, but a pure theft scenario may sit more naturally in a court action, particularly where the registrar or the gain-side registrar failed to apply adequate transfer controls.
We regularly advise registrants who discover a .ca transfer they never authorized. The first call they make — to us, to their registrar, or to CIRA — sets the pace of the recovery. Delay allows secondary transfers, privacy shielding, and monetization to compound the harm.
How does the CIRA CDRP test apply when a domain is stolen?
The CIRA CDRP is the mandatory administrative procedure for .ca disputes and requires the complainant to satisfy a confusing-similarity test centered on bad-faith registration. Specifically, the complainant must show: (1) the domain is confusingly similar to a mark or other protected name in which the complainant has rights; (2) the registrant registered the domain in bad faith; and (3) the complainant meets CIRA's Canadian Presence Requirements to hold a .ca domain.
That third element is not part of the UDRP and it is non-negotiable for .ca. CIRA's Canadian Presence Requirements restrict .ca registration to Canadian citizens, permanent residents, incorporated Canadian entities, and specified categories of legal presence in Canada. If you held the domain legitimately, you almost certainly already satisfy CPR. The CDRP panel will want confirmation of that eligibility in the evidentiary record, not a bare assertion.
For a theft scenario, the bad-faith element can be met by demonstrating that the transferee obtained or retained the domain through a fraudulent or unauthorized process. Panels applying the CDRP have treated unauthorized account access as a paradigm of bad faith. What this means practically: your complaint brief must document the original registration, the gap in authorization, and any communications from the thief or the gain-side registrar. A clean registration history plus a contemporaneous fraud report strengthens the bad-faith showing considerably.
If you are unsure whether your situation fits the CDRP path or requires a court action, email info@cognomenlaw.com for an initial read on the two routes.
What are the registrar-lock and transfer-reversal mechanics you must trigger immediately?
The registrar-lock escalation is the fastest interim protection available to a stolen-domain victim, and it operates entirely outside any formal dispute proceeding. The goal is to prevent a secondary transfer — a retransfer to a third party who may claim to be a good-faith purchaser — while you build the CDRP complaint or court filing.
The practical steps are sequential and time-critical. First, document the unauthorized state: screenshot the WHOIS/RDDS record, the registrar panel if you still have access, any authentication emails you did not initiate, and the current redirect destination. Second, contact both the losing registrar (where your account was held) and the gaining registrar (where the domain now sits) in writing, citing unauthorized transfer. Third, file a fraud report with CIRA's compliance team. CIRA's published abuse contacts are the appropriate channel; a phone call is not a substitute for a written record.
Many registrars will apply a voluntary hold once unauthorized transfer is credibly alleged. That hold is not guaranteed and does not itself reverse the transfer — but it stops the clock on secondary movement while you pursue the formal route. If the gaining registrar is unresponsive or offshore, court injunctive relief may be necessary to block a further transfer. That is a scenario where a court action overtakes the CDRP on pure speed grounds.
In our practice, the registrar-lock step has prevented retransfer in a significant share of theft matters. The clients who delay that escalation — even by 48 hours — face a materially harder path because the domain may have moved again or may have been registered to a different WHOIS entity.
When does a court route outperform the CDRP for a stolen .ca domain?
The CDRP is designed for abusive-registration disputes where the parties are identifiable and the registrant can receive service. It is an administrative procedure with no power to award damages, no ability to issue an injunction, and no mechanism to compel a non-responding registrar in another jurisdiction. Those limits define the situations where court is the faster or the only effective route.
Consider four contrasting situations. First: the thief is identifiable, the domain has not moved, you hold clear registration history, and the gaining registrar is CIRA-accredited — the CDRP is likely fastest. Second: the domain has been retransferred at least once, the current registrant claims to be a good-faith purchaser, and you need to freeze further movement by court order — a court injunction against the registrar or the current registrant is necessary before any arbitration can be useful. Third: the registrar's own security failure contributed to the compromise, and you want damages in addition to recovery — only a court can award monetary relief. Fourth: the domain is being used to send fraudulent invoices or phishing communications in your brand name, and you need an emergency injunction to stop the harm today — a court can move in hours where the CDRP cannot.
Court actions for .ca domain recovery are typically filed in the applicable Canadian federal or provincial court, and we work with local litigation counsel in the relevant jurisdiction to handle any in-court filings. We manage the dispute strategy, the evidence assembly, and the registrar escalation from COGNOMEN's side; local counsel handles the court appearance and any jurisdiction-specific procedure. That division keeps costs focused and avoids duplication.
In a recent matter (a .ca account-compromise theft, spring 2025), a secondary transfer had already occurred by the time the registrant contacted us. The CDRP timeline would not have reached a decision before a third transfer became possible. We coordinated an emergency injunction application through local litigation counsel, obtained a court-ordered registrar lock within days, and the domain was retransferred to the legitimate holder following the subsequent CDRP filing — a total process of roughly eleven weeks from first contact to completed retransfer.
If the domain has already moved more than once, or if you need emergency relief, contact info@cognomenlaw.com to weigh the court route against the CDRP for your specific situation.
What evidence decides a stolen .ca domain recovery?
The evidentiary record in a .ca theft matter differs from a standard CDRP complaint because the facts center on the event of compromise, not on the registrant's intent at the time of original registration. Building that record is the most important strategic step before filing anything.
The core evidence categories are these. First, chain-of-title: the original CIRA registration confirmation, renewal receipts, or invoice records showing your continuous ownership. Second, the unauthorized transfer evidence: WHOIS records captured before and after the transfer, authentication emails you did not initiate, registrar access logs if obtainable, and any ransom or buy-back communications from the party now holding the domain. Third, your Canadian Presence Requirements documentation: CIRA's CPR category must be confirmed in the submission. Fourth, the harm record: if the domain has been redirected, screenshots of the destination, email bounce reports, or any customer complaints received during the compromise period. Fifth, contemporaneous fraud reports: a police report or CIRA complaint filed at the time of discovery carries weight as a contemporaneous record that you treated the situation as unauthorized.
What panels and courts look for is a coherent narrative that the transfer was unauthorized — not merely disputed — and that the claimant held unambiguous prior entitlement. Gaps in that chain invite the other side to argue that you willingly transferred the domain, that the credentials were legitimately obtained, or that there is a competing entitlement. We have defended against exactly that kind of counter-narrative in .ca theft matters, and the strength of the contemporaneous documentation is what closes those arguments off.
Is the CDRP test the same as the UDRP, and does that matter for your case?
The CDRP tracks the UDRP in structure — the same three-element test, the same bad-faith factors, the same safe harbors for legitimate interest — but the Canadian Presence Requirements create a threshold that has no UDRP equivalent. For a theft victim, this means that even a clear case of unauthorized transfer can fail at the CDRP if CPR eligibility is not properly documented or if the complainant's CPR status has lapsed since the original registration.
There is also a substantive nuance at the bad-faith element. The UDRP requires registration and use in bad faith — both, cumulatively. The CDRP's treatment of this element in theft scenarios tends to focus on the nature of the transfer itself: a registration obtained by fraud is bad faith at the moment of the unauthorized transfer, regardless of what the domain is used for afterward. That framing can benefit a complainant who acts quickly, before the thief has had time to monetize or further use the domain.
The remedies under the CDRP are transfer or cancellation — the same as under the UDRP. There is no costs order, no monetary relief, and no finding that binds any court. If you need damages, a parallel or follow-on court action is required. And unlike the UDRP, the CDRP has no widely-published track record of Reverse Domain Name Hijacking findings — though the concept of abuse of process exists within CIRA's procedural rules.
Can you also pursue RDNH or a counterclaim if the recovery attempt against you is abusive?
Reverse Domain Name Hijacking (RDNH) is a finding that a complaint was filed in bad faith to strip a legitimate registrant of a domain they properly hold. It is available under the UDRP and under many ccTLD procedures. Within the CDRP framework, a respondent who believes the claim is pretextual — filed not because the domain was stolen but to extract a legitimate registration — can raise the abuse-of-process argument in the response.
We handle respondent-side .ca matters as well as recovery claims. In our practice, RDNH-adjacent situations in .ca typically arise when a brand owner discovers a domain held by a legitimate Canadian registrant who predates the complainant's mark claim, and files anyway — sometimes because counsel failed to assess the CPR issue or the timing of rights, sometimes as a deliberate pressure tactic. The CDRP does not award costs, but an abuse-of-process finding on the record has reputational consequences.
If you have received a CDRP complaint for a .ca domain you hold legitimately, the same evidence principles apply in reverse: document your original registration, your Canadian Presence Requirements category, and any use of the domain predating the complainant's trademark claim. A strong respondent record closes the path to transfer.
Related at COGNOMEN
Frequently asked questions about recovering a stolen .ca domain
Is it worth it to recover a stolen .ca domain?
For most brand owners and operating businesses, yes — the cost of a CDRP filing is modest relative to the value of an established .ca presence, accumulated SEO history, and customer trust in the domain. The decision turns on how the domain is used and what the compromise has cost in diverted traffic, bounced email, or customer confusion. We assess that trade-off at the outset so that the recovery strategy is proportionate to the actual stake. Where the domain has minimal remaining value or the evidence of theft is thin, we say so.
What are the most common mistakes when you recover a stolen .ca domain?
The most consequential mistake is delaying the registrar-lock escalation — every hour without a freeze creates risk of a secondary transfer that is far harder to unwind. The second is filing a CDRP complaint without first verifying that Canadian Presence Requirements documentation is current and attached to the submission; a CPR deficiency can defeat an otherwise strong complaint. The third is treating the CDRP as the only route without assessing whether emergency court relief is needed to prevent irreversible harm, such as a further transfer or active phishing from the domain.
Can a three-member panel change the outcome?
In a CDRP proceeding, a three-member panel is available at additional cost if either party requests it. A three-member panel is worth considering when the factual record is contested — for example, where the registrant disputes the claim of unauthorized transfer or raises a competing entitlement argument. Three panelists bring a more deliberative review and reduce the risk of an idiosyncratic result in a close case. For a clear theft with strong contemporaneous documentation, a single-member panel is typically sufficient and faster. The right choice depends on the specific facts, the complexity of the CPR issue, and the opposing party's likely posture.
About COGNOMEN
COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones — before WIPO, the Forum, CAC, ADNDRC, and national procedures including the CIRA CDRP — and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants, including respondent-side defense and matters where Reverse Domain Name Hijacking is the right argument. For stolen and hijacked domains, we escalate registrar locks, document account compromise, and pursue transfer reversal. To discuss a .ca theft or dispute, contact info@cognomenlaw.com.
Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.